Date: Thu, 24 Apr 2003 12:11:03 +0200 From: Pawel Jakub Dawidek <nick@garage.freebsd.pl> To: Peter <pfak@telus.net> Cc: freebsd-hackers@freebsd.org Subject: Re: Keeping a large shellbox stable and secure Message-ID: <20030424101103.GV20444@garage.freebsd.pl> In-Reply-To: <001901c309ee$36029070$c601a8c0@oxygen> References: <001901c309ee$36029070$c601a8c0@oxygen>
next in thread | previous in thread | raw e-mail | index | archive | help
--YttKMwf6abDJOSyE Content-Type: text/plain; charset=iso-8859-2 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Apr 23, 2003 at 04:15:20PM -0700, Peter wrote: +> Would ipfw2 or Ipfilter be better? Should I run RELENG_4 or RELENG_4_8. I suggest RELENG_4_8 of course. +> Any ideas would be appreciated. Basically, I'm attempting to make this b= ox +> as stable and secure as possible. Anything would be appreciated. If we are talking about security, take a look at CerbNG project: http://cerber.sourceforge.net But there is no stable release yet. You can find on this page also two different kernel modules: rexec and lrexec. Those two are stable, but not so functional and doesn't provide so high security level as CerbNG. --=20 Pawel Jakub Dawidek pawel@dawidek.net UNIX Systems Programmer/Administrator http://garage.freebsd.pl Am I Evil? Yes, I Am! http://cerber.sourceforge.net --YttKMwf6abDJOSyE Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iQCVAwUBPqe4Nz/PhmMH/Mf1AQETlwP8DDxiDZ03gFVet//auEui4WxAAdJdKEc/ jydV1LMgHu+mC39Nd6Rgsc2D6rkD80+Ks+fA9Ao+fQWvWSWtNFA1ohwM7KigYvdb uR3r5MiwknyQHgBFkaI8F3sZA5e3n1Ya1mWCjsGEk5GQqxKaRpNQ2lJUAUIG0/EM YRhnIfWIBpk= =QyOb -----END PGP SIGNATURE----- --YttKMwf6abDJOSyE--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030424101103.GV20444>